PT-2014-5935 · Sgminer+2 · Sgminer+2

Mick Ayzenberg

·

Publicado

2014-07-23

·

Atualizado

2015-08-28

·

CVE-2014-4502

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions sgminer versions prior to 4.2.2 cgminer versions prior to 4.3.5 BFGMiner versions prior to 4.1.0
Description The issue is related to multiple heap-based buffer overflows in the parse notify function. This can be triggered by remote pool servers sending a mining.subscribe response with a large or negative value in the Extranonc2 size parameter, followed by a crafted mining.notify request. The impact of this issue is unspecified.
Recommendations For sgminer versions prior to 4.2.2, update to version 4.2.2 or later. For cgminer versions prior to 4.3.5, update to version 4.3.5 or later. For BFGMiner versions prior to 4.1.0, update to version 4.1.0 or later.

Exploit

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-4502

Produtos afetados

Bfgminer
Cgminer
Sgminer